Allow shell/toolbox for all domains
Bug: 324142245 Test: m (presubmit) Change-Id: If408294d31c66241eca938ee2a681e6a9cf37ee2
This commit is contained in:
parent
f9f826fb30
commit
66c5beaecc
1 changed files with 29 additions and 0 deletions
|
@ -179,6 +179,35 @@ get_prop(domain, log_file_logger_prop)
|
|||
# Allow all processes to connect to PRNG seeder daemon.
|
||||
unix_socket_connect(domain, prng_seeder, prng_seeder)
|
||||
|
||||
# Allow calls to system(3), popen(3), ...
|
||||
allow {
|
||||
domain
|
||||
# Except domains that explicitly neverallow it.
|
||||
-kernel
|
||||
-init
|
||||
-vendor_init
|
||||
-app_zygote
|
||||
-webview_zygote
|
||||
-system_server
|
||||
-artd
|
||||
-audioserver
|
||||
-cameraserver
|
||||
-mediadrmserver
|
||||
-mediaextractor
|
||||
-mediametrics
|
||||
-mediaserver
|
||||
-mediatuner
|
||||
-mediatranscoding
|
||||
-ueventd
|
||||
-hal_audio_server
|
||||
-hal_camera_server
|
||||
-hal_cas_server
|
||||
-hal_codec2_server
|
||||
-hal_configstore_server
|
||||
-hal_drm_server
|
||||
-hal_omx_server
|
||||
} {shell_exec toolbox_exec}:file rx_file_perms;
|
||||
|
||||
# No domains other than a select few can access the misc_block_device. This
|
||||
# block device is reserved for OTA use.
|
||||
# Do not assert this rule on userdebug/eng builds, due to some devices using
|
||||
|
|
Loading…
Reference in a new issue